Digital Visibility Analysis forExposed Individuals
What can others find out about you?
Separate digital traces may appear harmless. When profiles, addresses, images, contact details and information about close connections are combined, they can create a practical attack surface. The Digital Visibility Analysis shows what can be found, which connections matter to your security and what you should address first.
One-time hybrid analysis for one protected person. Standard delivery time of 10 to 15 working days.

Technology finds traces. Experienced analysts turn them into a reliable exposure picture.
corma examines the digital footprint of exposed individuals from the perspective of potential adversaries. We research broadly, investigate relevant leads and verify whether a finding belongs to the right person. You receive a documented exposure picture, a threat assessment and concrete actions.
The Digital Visibility Analysis is a hybrid analysis. Professional research technology and AI-assisted functions help our analysts search and organise large volumes of information and identify connections.
Technology does not make security decisions. Our analysts direct the research, separate namesakes, assess sources and consider how a potential adversary could use the information. This professional judgement turns a search result into a reliable finding.
Why your own search is not enough
A search engine mainly shows isolated, familiar results. Automated scans broaden the search but may confuse people, repeat outdated information or highlight a technical finding that has little security relevance.
The material risk often lies in the connection between several traces.
A former address, an image with a location clue and information about close connections may reveal more together than any finding on its own. Our analysis identifies these connections and explains their relevance.
What we examine
The selection depends on your starting position and the agreed protection questions. Potential research areas include:
Identity and core data, including namesake separation
Public profiles, social media, online accounts and interactions
Addresses, contact details, locations, routines and relevant personal connections
Digital identities, data brokers and people-search services
Data breaches and indications of compromised credentials
Domains, historical websites and web archives
Dark web sources, forums and public messaging channels
Images, videos, media coverage and public appearances
Registers, holdings, sanctions lists, intellectual property rights and memberships
Not every area has the same relevance in every assignment. Our analysts focus on sources that help answer a concrete protection question.
How we work
The broad research uses professional research and analysis systems. AI-assisted functions may help with search, sorting, pattern recognition and connection. corma does not promise a fully automated AI analysis and does not produce an unverified AI summary as the client result. Our analysts set the search direction, verify sources and attribution, investigate relevant leads and assess security relevance.
1. Define the protection questions
We agree the protected person, starting data and research priorities with you in confidence.
2. Research and investigate
Our analysts search broadly and investigate relevant connections.
3. Verify and assess
We assess attribution, source context and strength of evidence. We then evaluate potential attack paths and prioritise actions.
4. Deliver the findings
You receive the full deliverable package and a discussion of the material findings and next steps.
What you receive
Your deliverable package
- •Main report with an overall assessment, methodology, detailed findings and recommended actions
- •Corma Risk Score on a scale from 1 to 10 and a prioritised risk assessment
- •Concise risk briefing for the protected person and responsible teams
- •Working register of digital traces, leak findings, actions, priorities and owners
- •Two visual overviews covering digital identity, visibility and risk signals
- •Annex explaining source context, evidence grades and the assessment framework
- •Source references, access dates and suitable evidence for material findings
What you can decide afterwards
The analysis does more than show where information appears. It answers four practical questions:
- Which findings can be reliably attributed to the protected person?
- What attack path could result?
- Which action has priority?
- Who should take responsibility for it?
The result provides a shared working basis for the protected person, Corporate Security, Executive Protection, IT and Data Protection.
Who the analysis is for
The analysis is designed for executives, board members, exposed entrepreneurs, public figures, political office holders, high-net-worth individuals and family offices. Clients may also include Corporate Security, Executive Protection, crisis teams, Data Protection and IT Security.
Executives and board members
Exposed entrepreneurs
Public figures and political office holders
High-net-worth individuals and family offices
Corporate Security and Executive Protection
Crisis teams, Data Protection and IT Security
Typical occasions
Preparing or reviewing a protection concept
Growing public visibility or a change of role
Concrete doxxing, stalking, threat or extortion indications
Suspected identity misuse or compromised credentials
Changes in personal or professional circumstances
A preventive assessment without a specific incident
corma GmbH
Your experts for digital security and online investigations

Jörn Weber
CEO & Founder
Why corma GmbH?
As an agency for online investigations and digital close protection, we offer you a well-founded basis to safeguard your digital identity.
Proven Expertise
Experience investigating complex digital matters, shaped by a background in investigative work
Hybrid Analysis
Professional research technology and experienced analysts work together, instead of relying on an automated scan
Confidential Service
Confidential handling of your information throughout the assignment
Terms
€6,000 net
plus applicable VAT, per protected person
10 to 15 working days
after the assignment begins and all required starting data has been received
The analysis is a snapshot at an agreed cut-off date. It does not include content removal, technical hardening of accounts or devices, continuous monitoring, incident response or legal advice. corma does not promise to find every digital trace that exists.
Would you like to know what information about a protected person can be found and connected?
In a confidential initial call, we define the protection questions, the secure exchange of information and a possible start date.
Blog
Clear Answers to Important Questions
Your most common questions: our answers
What is the Digital Visibility Analysis?
The Digital Visibility Analysis examines the digital footprint of an exposed individual from the perspective of potential adversaries. It shows what information can be found and connected, what security risks may result and which actions should come first.
What does hybrid analysis mean?
Hybrid analysis combines professional research technology with manual investigative and assessment work. Technical systems support the search, organisation and connection of information. Experienced analysts direct the research, verify attribution to the right person and assess the practical security relevance.
Is this an AI analysis?
No. corma may use AI-assisted functions within professional research and analysis systems. They support individual work steps but do not make professional judgements. Our analysts remain responsible for the search direction, verification, interpretation and risk assessment.
Why is my own Google search not enough?
A personal search usually returns separate results. It does not reliably establish whether a finding belongs to the right person, whether it is current or whether it has security relevance. Many risks arise only when several traces are connected. corma examines these connections.
What does the analysis cost?
The fixed fee for one protected person is €6,000 net plus applicable VAT. Broader assessments or additional services are agreed separately.
How long does the analysis take?
The standard delivery time is 10 to 15 working days after all required starting data has been received and the assignment has begun. Special protection questions or an unusual body of findings may require separate agreement.
Is continuous monitoring included?
No. The analysis is a one-time assessment at an agreed cut-off date. Continuous monitoring is a separate service and is included only when expressly agreed.
Can corma find every digital trace?
No. Sources may be inaccessible, unindexed, changed or deleted. Private content and closed areas are not readily accessible. corma documents the areas examined and explains material limitations but does not promise to identify every piece of information that exists.
Does corma remove information that it finds?
No. The standard service covers analysis, assessment and recommended actions. Removal, alteration or legal enforcement is not included and requires a separate service or suitable external specialists.
What information is needed to begin?
corma requires verified starting data for the protected person, the agreed protection questions and a named point of contact. This may include the full name, known name variations, professional roles, known profiles and other details suitable for attribution. The secure transfer method is agreed in advance.